
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has confirmed that ransomware gangs are additionally exploiting a high-severity Home windows Activity Host vulnerability that was flagged as actively exploited in April.
Activity Host is a core Home windows system element that permits DLL-based processes to run within the background and prevents information corruption by making certain they shut correctly throughout shutdown.
Tracked as CVE-2025-60710, this Home windows privilege escalation safety flaw was patched by Microsoft in November 2025 and stems from a link following weak spot that impacts Home windows 11 and Home windows Server 2025 gadgets.
Following profitable exploitation, native attackers with fundamental consumer permissions can achieve SYSTEM privileges and take full management of unpatched gadgets.
Whereas it did not share any particulars relating to ongoing assaults and Microsoft has but to replace its security advisory to substantiate in-the-wild exploitation, CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and gave Federal Civilian Government Department (FCEB) businesses two weeks to safe their techniques.
On Friday, CISA up to date its Identified Exploited Vulnerabilities Catalog (KEV) once more, flagging the safety vulnerability as being abused by ransomware gangs.
The U.S. cybersecurity company has not but shared any details about assaults concentrating on CVE-2025-60710, and a Microsoft spokesperson was not instantly out there for remark when BleepingComputer reached out earlier right this moment.
“Any such vulnerability is a frequent assault vector for malicious cyber actors and poses important dangers to the federal enterprise,” CISA warned. “Apply mitigations per vendor directions, comply with relevant BOD 22-01 steering for cloud providers, or discontinue use of the product if mitigations are unavailable.”
One week in the past, CISA additionally warned that ransomware gangs have begun exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659) after confirming energetic exploitation in early July.
Since November 2021, the company has flagged 383 actively exploited vulnerabilities in various Microsoft products, 112 of which have additionally been exploited in ransomware assaults.
Total prevention scores can disguise what occurs after preliminary entry. As soon as attackers are utilizing legitimate credentials, prevention drops sharply.
The Blue Report 2026 measures defenses method by method throughout 338 million simulations run in buyer manufacturing environments.

